Fun

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK

News Feed - 2024-05-15 05:05:19

Christopher Roark3 hours agoAlex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiKThe deployer account changed an Alex contract’s implementation address, and multiple tokens were subsequently drained from its bridge.887 Total views9 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAccording to a May 14 report from blockchain security platform CertiK, the Alex protocol bridge on the BNB Smart Chain network suffered $4.3 million in suspicious withdrawals just after its contract was suddenly upgraded.


Alex is a Bitcoin layer-2 protocol. According to its official website, it provides decentralized finance applications on Bitcoin. Its bridges are used to transfer assets from other networks, such as BNB Smart Chain and Ethereum, to its own network.


Blockchain data confirms that the Alex deployer account performed five identical upgrades to the “Bridge Endpoint” contract on BNB Smart Chain beginning at 3:56 pm UTC. Approximately $4.3 million worth of Binance-Pegged Bitcoin (BTC), USD Coin (USDC), and Sugar Kingdom Odyssey (SKO) were subsequently removed from the BNB Smart Chain side of the bridge.


Because the upgrade was performed by the protocol’s deployer account, CertiK labeled the event “a possible private key compromise.” Source: CertiK


The upgrade transaction changed the implementation address to one ending in 7058. The new implementation is unverified bytecode, making it unreadable to human beings.


About 48 minutes after these upgrades began, the proxy address for the bridge contract called an unverified function on an address ending in 4848E. This resulted in 16 BTC ($983,000 at current prices), 2.7 million SKO ($75,000) and $3.3 million worth of USDC at 4:44 pm, being moved into the address at 484E.


The attacker may also be attempting to drain funds on other networks. At 5:41 pm, just minutes after the suspicious upgrade on BNB Smart Chain, a similar series of Alex upgrades occurred on Ethereum. In this case, the deployer upgraded the “artist address” to an unverified contract. Immediately afterward, an account ending in 05ed attempted to make two withdrawals from the “team address.” These withdrawals failed, producing a “not owner” error.


The 05ed account had no history before May 10. It created one unverified contract on May 10 and two more on May 14, indicating that it may be under the control of a malicious user.


At the time of publication, the Alex team has not confirmed the exploit or commented on the incident.


The Alex bridge wasn’t the only protocol to face a potential exploit in May. On May 13, decentralized exchange Equalizer announced that it had lost more than 2,000 of its own tokens from an attacker who siphoned them away in small increments over several days. The Gnus.ai hack on May 6 also resulted in $1.27 million worth of losses.


Related:CertiK discovered $5M security flaw in Wormhole bridge on Aptos# Bitcoin# Blockchain# Ethereum# Hackers# Private Keys# Cybersecurity# Hacks# DeFi# Layer2Add reaction

News Feed

Analyst Says PEPE Price Must Break This Resistance Level For 150% Surge Toward ATHs
Este artículo también está disponible en español. The PEPE price is currently trading within a Falling Wedge pattern, a historically bullish indicator that suggests an im
Brazilian Crypto Investment Platform Bluebenx Backpedals on Hack Reports, States It Was Victim of a Listing Scam
Brazilian Crypto Investment Platform Bluebenx Backpedals on Hack Reports, States It Was Victim of a Listing Scam Bluebenx, a Brazilian crypto company that recently stopped customer
Expect Bitcoin ETF options to launch before 2025
Alex O’Donnell1 hour agoExpect Bitcoin ETF options to launch before 2025You can expect Bitcoin ETF options to begin trading in the United States before 2025.491 Total views8 Total sharesListen to article 0:00OpinionOwn
Biggest Movers: LEO Hits 6-Week High, as NEAR Jumps Higher for Third Straight Session
Biggest Movers: LEO Hits 6-Week High, as NEAR Jumps Higher for Third Straight Session LEO rose to a six-week high on Wednesday, as prices rallied for a fifth consecutive session. T
BRICS Nations Push to Expand Global Influence to Counter the West’s ‘Destructive Actions’
BRICS Nations Push to Expand Global Influence to Counter the West"s "Destructive Actions" The BRICS nations are focusing on increasing their international roles and “enhancing co
Targeting the US Dollar’s Hegemony: Russia, China, and BRICS Nations Plan to Craft a New International Reserve Currency
Targeting the US Dollar’s Hegemony: Russia, China, and BRICS Nations Plan to Craft a New International Reserve Currency While inflation data in Europe and the U.S. has risen sign
Former Monero Developer Spagni Released From US Prison, Pledges to Address Fraud Allegations
Former Monero Developer Spagni Released From US Prison, Pledges to Address Fraud Allegations Former Monero developer Riccardo Spagni has been released from a U.S. prison where he r
Bitcoin, Ethereum Technical Analysis: ETH Drops Below $1,800, BTC Once Again Falls Under $30K
Bitcoin, Ethereum Technical Analysis: ETH Drops Below $1,800, BTC Once Again Falls Under $30K Despite a strong start to the week, bitcoin fell below $30,000 on Thursday, as crypto
Subhash Chandra Garg on the Future of Crypto
Subhash Chandra Garg on the Future of Crypto India’s former Finance Secretary Subhash Chandra Garg has shared his views on the future of cryptocurrency, both in India and w
Zhiyuan Sun5 hours agoBitdeer’s losses widen in Q2 after one-time $33M listing fee, shares up 44%The company entered into a $150 million share purchase agreement with B. Riley Financial on Aug. 10.2769 Total views14 To
Why Isn’t XRP Skyrocketing? Expert Explains The Hidden Forces
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Sichuan’s Blockchain Park: Chengdu Government Officials Welcome Bitcoin Miners
Sichuan"s Blockchain Park: Chengdu Government Officials Welcome Bitcoin MinersIn mid-August officials from the Chinese province of Sichuan approved a number of enterprises that mine